# VulnClaw MCP Services Integration: The 4 Built-in Tools Explained

> Explore VulnClaw's MCP services: fetch, memory, chrome-devtools, and burp. Enable HTTP testing, persistent storage, browser automation, and traffic interception with this powerful integration.

- Repository: [Unclecheng/VulnClaw](https://github.com/Unclecheng-li/VulnClaw)
- Tags: deep-dive
- Published: 2026-06-30

---

**VulnClaw ships with a built-in MCP (Modular Command Protocol) subsystem that supports four services—fetch, memory, chrome-devtools, and burp—enabling HTTP testing, persistent storage, browser automation, and traffic interception.**

The [Unclecheng-li/VulnClaw](https://github.com/Unclecheng-li/VulnClaw) repository implements a modular **MCP services** architecture designed to unify external security tools under a single protocol. This subsystem allows security researchers to orchestrate network requests, browser automation, and proxy-based testing through standardized tool definitions exposed via the Web UI backend.

## Understanding VulnClaw's MCP Architecture

At startup, VulnClaw initializes an `MCPLifecycleManager` that reads service definitions from the `mcp.servers` configuration block. According to the source code in [`vulnclaw/mcp/lifecycle.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/mcp/lifecycle.py), this manager handles the startup, monitoring, and shutdown of MCP server processes. The registry module at [`vulnclaw/mcp/registry.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/mcp/registry.py) maintains a catalog of available servers and the specific tools each exposes.

The diagnostics routine, implemented in [`vulnclaw/web/services/mcp_service.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/web/services/mcp_service.py), provides runtime visibility through the `get_mcp_diagnostics()` function. This builds a `MCPDiagnosticsView` containing service states, tool counts, and health information accessible via the Web UI. For human-readable setup instructions, refer to [`docs/mcp-deployment.md`](https://github.com/Unclecheng-li/VulnClaw/blob/main/docs/mcp-deployment.md) in the repository root.

## The Four Built-in MCP Services

VulnClaw supports four distinct MCP service execution modes, ranging from built-in local handlers to external stdio and sse-based servers.

### Fetch Service (HTTP Testing)

The **fetch** service operates in local mode using `httpx` for simple HTTP requests and API testing. Built-in and enabled by default, this service requires no external dependencies. It provides immediate network probing capabilities without additional configuration.

### Memory Service (Persistent Storage)

The **memory** service maintains cross-session persistent storage using local JSON files. Also built-in and enabled by default, this service allows tools to retain state between VulnClaw sessions, storing data in the user's configuration directory.

### Chrome DevTools Service (Browser Automation)

The **chrome-devtools** service enables browser automation, JavaScript execution, screenshot capture, and performance analysis. This service runs as an `stdio` MCP server using Node.js and auto-installs via `npx` when enabled. It exposes 31+ tools, including `chrome-open-and-screenshot` for automated page capture.

Unlike the built-in services, chrome-devtools requires an external Chrome instance running with remote debugging enabled on port 9222.

### Burp Service (Traffic Interception)

The **burp** service provides HTTP traffic interception, replay, and scanning capabilities as a drop-in replacement for Yakit. Implemented as an `sse` MCP server using Java, this service requires an external Burp Suite extension to be installed and running. It connects via Server-Sent Events to integrate Burp's proxy functionality into VulnClaw workflows.

## Configuring MCP Services in VulnClaw

Service configurations reside in the user configuration file under the `mcp.servers` key, typically located at `~/.vulnclaw/config.yaml`.

### Service Definitions and Configuration Files

To enable the Chrome DevTools service, add the following configuration block:

```yaml
mcp:
  servers:
    chrome-devtools:
      enabled: true
      transport:
        type: stdio
        command: npx
        args:
          - "-y"
          - "chrome-devtools-mcp@latest"
          - "--browser-url=http://127.0.0.1:9222"

```

The burp service follows a similar pattern but uses `sse` transport type and requires connection details for the Burp Suite extension.

### Enabling Services via CLI

VulnClaw provides a command-line interface for quick configuration changes without editing YAML files directly:

```bash
vulnclaw config set mcp.servers.burp.enabled true

```

## Accessing MCP Diagnostics Programmatically

The [`vulnclaw/web/services/mcp_service.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/web/services/mcp_service.py) module exposes the `get_mcp_diagnostics()` function for runtime inspection of service health:

```python
from vulnclaw.web.services.mcp_service import get_mcp_diagnostics

diagnostics = get_mcp_diagnostics()
print(f"Total services: {diagnostics.total_services}")
for svc in diagnostics.services:
    print(f"- {svc.name} (enabled={svc.enabled}) – "
          f"mode={svc.execution_mode}, tools={svc.tool_count}")

```

This returns a `MCPDiagnosticsView` object containing the total service count, individual service states, execution modes, and available tool counts for each registered MCP service.

## Executing MCP Tools in Security Workflows

Once services are enabled, VulnClaw exposes their tools through the task service. For example, to capture a screenshot using the Chrome DevTools service:

```python
from vulnclaw.web.services.task_service import run_task

run_task("chrome-open-and-screenshot", {"url": "http://example.com"})

```

This executes the `chrome-open-and-screenshot` tool provided by the chrome-devtools MCP server, returning the screenshot data through VulnClaw's standard task pipeline.

## Summary

- VulnClaw integrates four **MCP services**: fetch (local HTTP), memory (JSON persistence), chrome-devtools (browser automation), and burp (traffic interception).
- Service definitions live in `mcp.servers` configuration, managed by `MCPLifecycleManager` in [`vulnclaw/mcp/lifecycle.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/mcp/lifecycle.py).
- Runtime diagnostics are available via `get_mcp_diagnostics()` in [`vulnclaw/web/services/mcp_service.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/web/services/mcp_service.py).
- Chrome DevTools requires Node.js and external Chrome debugging port; Burp requires the Burp Suite MCP extension.
- Tools from enabled services are accessible programmatically through `run_task()` in [`vulnclaw/web/services/task_service.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/web/services/task_service.py).

## Frequently Asked Questions

### What MCP services does VulnClaw support by default?

VulnClaw supports four MCP services out-of-the-box: **fetch** for HTTP testing via `httpx`, **memory** for JSON-based persistent storage, **chrome-devtools** for browser automation via Node.js stdio, and **burp** for HTTP interception via SSE. The fetch and memory services are built-in and enabled by default, while chrome-devtools and burp require external dependencies.

### How do I enable the Chrome DevTools MCP service in VulnClaw?

Enable the Chrome DevTools service by setting `mcp.servers.chrome-devtools.enabled` to `true` in `~/.vulnclaw/config.yaml` with stdio transport configured to run `npx chrome-devtools-mcp@latest`. You must also have Chrome running with remote debugging enabled on `http://127.0.0.1:9222` for the service to function.

### Where are MCP service configurations stored in VulnClaw?

MCP service configurations are stored in the user configuration file under the `mcp.servers` key, typically located at `~/.vulnclaw/config.yaml`. The `MCPLifecycleManager` reads these definitions at startup to initialize the appropriate server processes.

### Can I use Burp Suite Professional with VulnClaw's MCP integration?

Yes, the burp service acts as a drop-in replacement for Yakit and supports Burp Suite Professional through the MCP extension. Configure it by enabling `mcp.servers.burp` with `sse` transport type, ensuring the Burp Suite MCP extension is installed and running to handle the Server-Sent Events connection.